{"id":"T1687","name":"Exploitation for Defense Impairment","url":"https://attack.mitre.org/techniques/T1687","tactics":["defense-impairment"],"platforms":["IaaS","Linux","macOS","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0900","stix_id":"x-mitre-detection-strategy--3a3820cd-260b-43d0-b5af-89b7ba81a044","name":"Detection of Defense Impairment","url":"https://attack.mitre.org/detectionstrategies/DET0900","analytics":[{"id":"AN2038","stix_id":"x-mitre-analytic--7ec436a3-dd31-4d23-a51b-0e03d3c474bd","name":"Analytic 2038","description":"Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.","url":"https://attack.mitre.org/detectionstrategies/DET0900#AN2038","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=7035","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"CrashCorrelationWindow","description":"Time between suspicious interaction and security service failure"},{"field":"ProtectedServiceList","description":"Security agents/services expected to remain stable"},{"field":"TelemetryGapThreshold","description":"Acceptable heartbeat silence duration"}],"live":true,"detection_strategies":["DET0900"],"techniques":["T1687"]},{"id":"AN2039","stix_id":"x-mitre-analytic--c6fb992c-387e-49ee-beaf-a1351aded262","name":"Analytic 2039","description":"Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation.","url":"https://attack.mitre.org/detectionstrategies/DET0900#AN2039","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"execve, kill, ptrace, insmod, rmmod targeting security processes","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:DAEMON","channel":"auditd stopped, config changed, logging suspended","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"auditd-daemon"}],"mutable_elements":[{"field":"ProtectedProcessNames","description":"Names of EDR, audit, AV, firewall daemons"},{"field":"ModuleUnloadAllowlist","description":"Approved maintenance unload operations"},{"field":"HealthGapThreshold","description":"Expected telemetry heartbeat tolerance"}],"live":true,"detection_strategies":["DET0900"],"techniques":["T1687"]},{"id":"AN2042","stix_id":"x-mitre-analytic--f46639b5-4d99-4d52-8da9-112a468cc6d8","name":"Analytic 2042","description":"Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction.","url":"https://attack.mitre.org/detectionstrategies/DET0900#AN2042","platforms":["SaaS"],"log_source_references":[{"name":"saas:okta","channel":"policy.rule.update;system.log.disable;admin.role.assign","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-okta"},{"name":"m365:unified","channel":"Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"PrivilegedActorAllowlist","description":"Approved admins allowed to change controls"},{"field":"RetentionChangeThreshold","description":"Minimum acceptable logging retention"}],"live":true,"detection_strategies":["DET0900"],"techniques":["T1687"]},{"id":"AN2040","stix_id":"x-mitre-analytic--9df50fd3-bbad-43ce-b511-1bf995f1b583","name":"Analytic 2040","description":"Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.","url":"https://attack.mitre.org/detectionstrategies/DET0900#AN2040","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Crash or abnormal termination of security agent or system extension host","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Extension disabled, unloaded, failed to start","data_component":"DC0074","data_component_name":"Driver Metadata","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Traffic spike preceding control crash","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ExtensionList","description":"Protected security system extensions"},{"field":"CrashBurstThreshold","description":"Multiple failures in short interval"}],"live":true,"detection_strategies":["DET0900"],"techniques":["T1687"]},{"id":"AN2041","stix_id":"x-mitre-analytic--47df93f9-b33f-4333-95b6-b3cca9418a4d","name":"Analytic 2041","description":"Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage.","url":"https://attack.mitre.org/detectionstrategies/DET0900#AN2041","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"StopLogging, DeleteTrail, or DisableSecurityService","data_component":"DC0090","data_component_name":"Cloud Service Disable","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"ModifyInstanceAttribute","data_component":"DC0073","data_component_name":"Instance Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"AuthorizeSecurityGroupIngress","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"CriticalTrailList","description":"Audit trails that must remain enabled"},{"field":"ControlChangeWindow","description":"Time after suspicious API sequence to inspect coverage loss"}],"live":true,"detection_strategies":["DET0900"],"techniques":["T1687"]}],"live":true,"version":"1.0","techniques":["T1687"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}